Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

Cybersecurity researchers have identified a malicious npm supply chain campaign involving eight packages that have been downloaded over 40,000 times. The packages, linked to a threat actor named 'Malfex,' deliver remote access trojans and data-stealing malware to compromised systems.
Why it matters
Supply chain attacks targeting open-source repositories pose a significant risk to software developers and enterprise security by injecting malicious code into legitimate development workflows.
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts.
The campaign has been codenamed MALFEX by CloudSEK and Checkmarx . The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have been flagged as malicious.
The list of identified malicious packages is below -
In all, these packages have been collectively downloaded 40,767 times. Of these, 37,419 downloads correspond to "function-flag," making it the largest driver of this activity. The package was first published in July 2024. The latest version was released on August 4, 2025.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in